Aller au contenu

Fiche vulnérabilité

CVE-2021-38618 : vulnérabilité élevée (CVSS 7.4)

Description

In GFOS Workforce Management 4.8.272.1, the login page of application is prone to authentication bypass, allowing anyone (who knows a user's credentials except the password) to get access to an account. This occurs because of JSESSIONID mismanagement.

En bref

Sévérité
Élevée (CVSS 7.4)
Vecteur CVSS
CVSS:3.1/AC:H/AV:N/A:N/C:H/I:H/PR:N/S:U/UI:N
Exploitation active
Non signalée par la CISA
Publication
4 oct. 2021
Dernière mise à jour
30 mai 2025

Références

Rechercher une autre vulnérabilité dans la base CVE